hf-mcp

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs the official 'huggingface-hub' package via the 'uv' package manager. This is a standard procedure for enabling Hugging Face CLI functionality.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of scripts and commands on remote Hugging Face GPU/CPU infrastructure via the 'hf_jobs' tool. While this involves command execution, it is the intended primary purpose of the skill (providing access to cloud compute) and is performed within the controlled environment of Hugging Face's platform.
  • [SAFE]: References to external documentation and setup URLs (huggingface.co/docs, huggingface.co/settings) point to official and trusted domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 06:05 PM
Security Audit — agent-trust-hub — hf-mcp